
TOP Alle Bugbounty-Pentesting CVE-2023- POC Exp RCE Beispiel-Payload Dinge
alle Top Top Top_Codeql TOP Alle bugbounty pentesting CVE-2022- POC Exp Dinge
| Wechat Pay | AliPay | Paypal | BTC Pay | BCH Pay |
|---|---|---|---|---|
| paypal [email protected] |
| star | updated_at | name | url | des |
|---|
| 4060 | 2026-09-05T18:54:27Z | copy-fail-CVE-2026-31431 | https://github.com/theori-io/copy-fail-CVE-2026-31431 | Copy Fail (CVE-2026-31431): 9 Jahre alte Linux-Kernel-LPE, entdeckt von Theorís Xint Code |
| 916 | 2026-09-02T14:29:52Z | wp2shell-PoC | https://github.com/sowarma/wp2shell-PoC | CVE-2026-63030 & CVE-2026-60137 RCE-Kette Proof-of-Concept |
| 772 | 2026-09-05T23:36:29Z | wp2shell-poc | https://github.com/Icex0/wp2shell-poc | wp2shell (CVE-2026-63030 & CVE-2026-60137) - vollständige RCE-Kette |
| 181 | 2026-08-20T10:42:34Z | next-16.2.4-pocs | https://github.com/dwisiswant0/next-16.2.4-pocs | Next.js v16.2.4 Security PoC Sammlung (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) |
| 933 | 2026-09-05T19:06:56Z | BYOVD | https://github.com/BlackSnufkin/BYOVD | BYOVD-Forschungsanwendungsfälle mit Erkennung anfälliger Treiber und Reverse-Engineering-Methodik. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501). |
| 572 | 2026-09-04T17:20:17Z | cve_2026_31431 | https://github.com/rootsecdev/cve_2026_31431 | Exploit POC für CVE_2026_31431 |
| 739 | 2026-09-06T02:36:18Z | ghostlock-app | https://github.com/YuKongA/ghostlock-app | GhostLock One-Tap-Ausführungs-App (CVE-2026-43499) |
| 326 | 2026-09-03T07:37:39Z | CVE-2026-54121 | https://github.com/aniqfakhrul/CVE-2026-54121 | Certighost POC |
| 532 | 2026-09-03T19:17:51Z | cve-2026-41940-PoC | https://github.com/lanicer/cve-2026-41940-PoC | Ein cPanel- und WHM-Authentifizierungsumgehungstool |
| 239 | 2026-09-05T22:29:13Z | CVE-2026-43499-popsicle | https://github.com/x-spy/CVE-2026-43499-popsicle | CVE-2026-43499 Implementierung für 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k |
| 212 | 2026-08-24T15:13:49Z | CVE-2026-41089 | https://github.com/0xABCD01/CVE-2026-41089 | CVE-2026-41089 PoC — Netlogon CLDAP Stack-Pufferüberlauf (CVSS 9.8 KRITISCH) |
| 259 | 2026-09-02T02:28:06Z | CVE-2026-21858 | https://github.com/Chocapikk/CVE-2026-21858 | n8n Ni8mare - Unauthentifizierter beliebiger Datei-Lesezugriff bis RCE-Kette (CVSS 10.0) |
| 1113 | 2026-09-06T01:24:04Z | Root-My-Galaxy | https://github.com/BuSung-dev/Root-My-Galaxy | KSU-Installer für unterstützte Samsung Galaxy Firmware mit CVE-2026-43499 |
| 262 | 2026-08-30T07:08:06Z | CVE-2026-40369-EXPLOIT | https://github.com/orinimron123/CVE-2026-40369-EXPLOIT | Vollständiger Exploit-Code für CVE-2026-40369 - Eine Windows-Kernel-Schwachstelle für beliebiges Schreiben, die eine Browser-Sandbox-Escape aus dem Render-Prozess-Sandbox aller Browser ermöglicht |
| 207 | 2026-09-03T10:13:28Z | CVE-2026-24061 | https://github.com/SafeBreach-Labs/CVE-2026-24061 | Ausnutzung von CVE-2026-24061 |
| 156 | 2026-09-05T22:29:10Z | CVE-2026-43499 | https://github.com/MobiusM/CVE-2026-43499 | CVE-2026-43499 PoC |
| 361 | 2026-08-31T10:04:28Z | copyfail-go | https://github.com/badsectorlabs/copyfail-go | Eine Go-Implementierung von copyfail (CVE-2026-31431) |
| 174 | 2026-09-04T12:54:40Z | CVE-2026-62911 | https://github.com/hypnguyen1209/CVE-2026-62911 | POC Pre-Auth RCE auf Exchange |
| 106 | 2026-09-02T14:50:34Z | wp2shell | https://github.com/0xsha/wp2shell | CVE-2026-63030 + CVE-2026-60137 - „wp2shell“: unauthentifizierte RCE im WordPress-Kern |
| 824 | 2026-08-29T02:46:00Z | CVE-2026-24061 | https://github.com/jacubes/CVE-2026-24061 | CVE-2026-24061 Exploit PoC |
| 496 | 2026-09-04T11:37:28Z | cPanelSniper | https://github.com/ynsmroztas/cPanelSniper | CVE-2026-41940 — cPanel & WHM Authentifizierungsumgehung über Session-File-CRLF-Injection |
| 88 | 2026-09-05T14:30:39Z | CVE-2026-75604-poc | https://github.com/rafabd1/CVE-2026-75604-poc | CVE-2026-75604 Next.js Windows RCE poc |
| 212 | 2026-09-05T15:31:02Z | ResetNightmare | https://github.com/Semperis-Community/ResetNightmare | POC-Tool für ResetNightmare (CVE-2026-27912) |
| 128 | 2026-08-19T06:30:54Z | CVE-2026-20817 | https://github.com/oxfemale/CVE-2026-20817 | Windows Error Reporting ALPC Rechteerweiterung (CVE-2026-20817) - Proof-of-Concept-Exploit, der lokale Rechteerweiterung über den WER-Dienst demonstriert. |
| 317 | 2026-09-06T01:32:07Z | Root-My-Pixel | https://github.com/alex193a/Root-My-Pixel | Jailbreak unterstützter Google Pixel-Telefone mit CVE-2026-43499 |
| 101 | 2026-09-04T19:55:40Z | CVE-2026-42980-POC | https://github.com/G4sp4rCS/CVE-2026-42980-POC | CVE-2026-42980 ÖFFENTLICHER EXPLOIT + FORSCHUNG |
| 46 | 2026-09-03T14:49:43Z | samsung-android-lpe | https://github.com/Vikramaditya015/samsung-android-lpe | Poc für CVE-2026-20980, CVE-2026-20981, CVE-2026-20982 |
| 61 | 2026-09-05T16:57:13Z | wp2shell-scanner | https://github.com/ZephrFish/wp2shell-scanner | CVE-2026-63030, CVE-2026-60137, wp2shell Scanner |
| 111 | 2026-08-30T13:42:25Z | CVE-2026-31431-Advanced-Exploit | https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit | CVE-2026-31431 纯文件利用 |
| 120 | 2026-09-03T20:31:36Z | CVE-2026-41651 | https://github.com/Vozec/CVE-2026-41651 |
| star | updated_at | name | url | des |
|---|
| 1431 | 2026-09-01T11:54:27Z | CVE-2025-55182 | https://github.com/msanft/CVE-2025-55182 | Erklärung und vollständiger RCE PoC für CVE-2025-55182 |
| 2458 | 2026-09-05T16:31:41Z | react2shell-scanner | https://github.com/assetnote/react2shell-scanner | Hochpräziser Erkennungsmechanismus für RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) |
| 793 | 2026-08-24T12:23:34Z | CVE-2025-55182-research | https://github.com/ejpir/CVE-2025-55182-research | CVE-2025-55182 POC |
| 493 | 2026-08-11T09:12:24Z | CVE-2018-20250 | https://github.com/WyAtu/CVE-2018-20250 | exp für https://research.checkpoint.com/extracting-code-execution-from-winrar |
| 716 | 2026-09-02T03:40:10Z | CVE-2025-33073 | https://github.com/mverschu/CVE-2025-33073 | PoC-Exploit für die NTLM-Reflection-SMB-Schwachstelle. |
| 933 | 2026-09-05T19:06:56Z | BYOVD | https://github.com/BlackSnufkin/BYOVD | BYOVD-Forschungsanwendungsfälle mit Erkennung anfälliger Treiber und Reverse-Engineering-Methodik. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501). |
| 530 | 2026-08-30T23:03:21Z | CVE-2025-32463_chwoot | https://github.com/pr0v3rbs/CVE-2025-32463_chwoot | Rechteerweiterung zu root über die sudo-Binary mit chroot-Option. CVE-2025-32463 |
| 250 | 2026-08-23T00:40:02Z | IngressNightmare-PoC | https://github.com/hakaioffsec/IngressNightmare-PoC | Dies ist ein PoC-Code zur Ausnutzung der IngressNightmare-Schwachstellen (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 und CVE-2025-1974). |
| 344 | 2026-08-24T14:52:54Z | redis_exploit | https://github.com/raminfp/redis_exploit | CVE-2025-49844 (RediShell) |
| 476 | 2026-09-05T19:01:51Z | CVE-2025-32463 | https://github.com/kh4sh3i/CVE-2025-32463 | Lokale Rechteerweiterung zu Root über Sudo chroot unter Linux |
| 268 | 2026-08-24T14:52:49Z | CVE-2025-48799 | https://github.com/Wh04m1001/CVE-2025-48799 | |
| 315 | 2026-08-15T22:24:28Z | CVE-2025-53770-Exploit | https://github.com/soltanali0/CVE-2025-53770-Exploit | SharePoint WebPart Injection Exploit-Tool |
| 142 | 2026-08-14T00:51:12Z | Nextjs_RCE_Exploit_Tool | https://github.com/pyroxenites/Nextjs_RCE_Exploit_Tool | Exploit für CVE-2025-55182 & CVE-2025-66478 |
| 316 | 2026-08-29T00:10:14Z | CVE-2025-55182 | https://github.com/emredavut/CVE-2025-55182 | RSC/Next.js RCE-Schwachstellen-Detektor & PoC Chrome-Erweiterung – CVE-2025-55182 & CVE-2025-66478 |
| 1058 | 2026-08-29T11:37:43Z | React2Shell-CVE-2025-55182-original-poc | https://github.com/lachlan2k/React2Shell-CVE-2025-55182-original-poc | Original Proof-of-Concepts für React2Shell CVE-2025-55182 |
| 408 | 2026-09-04T04:29:58Z | CVE-2025-24071_PoC | https://github.com/0x6rss/CVE-2025-24071_PoC | CVE-2025-24071: NTLM-Hash-Leak über RAR/ZIP-Extraktion und .library-ms-Datei |
| 164 | 2026-07-15T09:04:59Z | AirBorne-PoC | https://github.com/ekomsSavior/AirBorne-PoC | poc für CVE-2025-24252 & CVE-2025-24132 |
| 198 | 2026-08-06T15:21:14Z | CVE-2025-21298 | https://github.com/ynwarcs/CVE-2025-21298 | Proof of Concept & Details für CVE-2025-21298 |
| 215 | 2026-08-17T06:27:29Z | CVE-2025-32023 | https://github.com/leesh3288/CVE-2025-32023 | PoC & Exploit für CVE-2025-32023 / PlaidCTF 2025 „Zerodeo“ |
| 202 | 2026-09-02T23:45:49Z | iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201 | https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201 | CVE-2025-31200 ist eine Zero-Day-, Zero-Click-RCE in iOS CoreAudio's AudioConverterService, ausgelöst durch eine bösartige Audiodatei über iMessage/SMS. Die Ausnutzung umging Blastdoor, ermöglichte Kernel-Eskalation (CVE-2025-31201) und erlaubte Token-Diebstahl bis zum Patch in iOS 18.4.1 (16. April 2025). |
| 196 | 2026-07-20T18:42:16Z | CVE-2025-30208-EXP | https://github.com/ThumpBo/CVE-2025-30208-EXP | CVE-2025-30208-EXP |
| 190 | 2026-03-25T19:46:42Z | RSC-Detect-CVE-2025-55182 | https://github.com/alptexans/RSC-Detect-CVE-2025-55182 | RSC Detect CVE 2025 55182 |
| 385 | 2026-08-11T06:04:12Z | ColorOS-CVE-2025-10184 | https://github.com/yuuouu/ColorOS-CVE-2025-10184 | ColorOS短信漏洞,以及用户自救方案 |
| 283 | 2026-08-31T11:32:54Z | CVE-2025-55182-advanced-scanner- | https://github.com/zack0x01/CVE-2025-55182-advanced-scanner- | |
| 432 | 2026-08-30T22:41:40Z | Next.js-RSC-RCE-Scanner-CVE-2025-66478 | https://github.com/Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478 | Ein Kommandozeilen-Scanner zur Batch-Erkennung von Next.js-Anwendungsversionen und zur Bestimmung, ob sie von der CVE-2025-66478-Schwachstelle betroffen sind. |
| 197 | 2026-08-27T11:19:26Z | POC-CVE-2025-24813 | https://github.com/absholi7ly/POC-CVE-2025-24813 | Dieses Repository enthält ein automatisiertes Proof-of-Concept-(PoC)-Skript zur Ausnutzung von CVE-2025-24813, einer Remote-Code-Execution-(RCE)-Schwachstelle in Apache Tomcat. Die Schwachstelle ermöglicht es einem Angreifer, eine bösartige serialisierte Payload auf den Server hochzuladen, was bei Erfüllung bestimmter Bedingungen zu beliebiger Codeausführung über Deserialisierung führt. |
| 151 | 2026-07-23T05:00:18Z | CVE-2025-11001 | https://github.com/pacbypass/CVE-2025-11001 | Exploit für CVE-2025-11001 oder CVE-2025-11002 |
| 91 | 2026-08-03T04:47:49Z | IngressNightmare-POCs | https://github.com/sandumjacob/IngressNightmare-POCs | CVE-2025-1974 |
| 232 | 2026-09-03T19:51:55Z | CVE-2025-21333-POC | https://github.com/MrAle98/CVE-2025-21333-POC | POC-Exploit für CVE-2025-21333 Heap-basierten Pufferüberlauf. Es nutzt WNF-Statusdaten und I/O-Ring IOP_MC_BUFFER_ENTRY |
| 354 | 2026-08-25T14:17:44Z | o3_finds_cve-2025-37899 | https://github.com/SeanHeelan/o3_finds_cve-2025-37899 | Artefakte für den Blogbeitrag über das Auffinden von CVE-2025-37899 mit o3 |
| star | updated_at | name | url | des |
|---|
| 2458 | 2026-09-01T15:26:46Z | CVE-2024-1086 | https://github.com/Notselwyn/CVE-2024-1086 | Universeller Proof-of-Concept-Exploit für lokale Rechteerweiterung für CVE-2024-1086, funktioniert auf den meisten Linux-Kerneln zwischen v5.14 und v6.6, einschließlich Debian, Ubuntu und KernelCTF. Die Erfolgsrate beträgt 99,4 % in KernelCTF-Images. |
| 692 | 2026-09-01T03:08:23Z | CVE-2024-38063 | https://github.com/ynwarcs/CVE-2024-38063 | poc für CVE-2024-38063 (RCE in tcpip.sys) |
| 497 | 2026-09-04T20:23:59Z | cve-2024-6387-poc | https://github.com/zgzhang/cve-2024-6387-poc | eine Signal-Handler-Race-Condition im OpenSSH-Server (sshd) |
| 520 | 2026-08-21T18:07:43Z | CVE-2024-49113 | https://github.com/SafeBreach-Labs/CVE-2024-49113 | LdapNightmare ist ein PoC-Tool, das einen anfälligen Windows Server gegen CVE-2024-49113 testet |
| 533 | 2026-07-10T06:04:54Z | git_rce | https://github.com/amalmurali47/git_rce | Exploit PoC für CVE-2024-32002 |
| 528 | 2026-09-02T11:37:54Z | CVE-2024-6387_Check | https://github.com/xaitax/CVE-2024-6387_Check | CVE-2024-6387_Check ist ein leichtgewichtiges, effizientes Tool zur Identifizierung von Servern, die anfällige Versionen von OpenSSH ausführen |
| 224 | 2026-08-24T14:52:32Z | CVE-2024-38077 | https://github.com/qi4L/CVE-2024-38077 | RDL的堆溢出导致的RCE |
| 335 | 2026-08-15T23:13:07Z | CVE-2024-21338 | https://github.com/hakaioffsec/CVE-2024-21338 | Lokale Rechteerweiterung von Admin zu Kernel-Schwachstelle auf Windows 10 und Windows 11 Betriebssystemen mit aktiviertem HVCI. |
| 378 | 2026-09-02T00:38:43Z | cve-2024-6387-poc | https://github.com/acrono/cve-2024-6387-poc | 32-Bit PoC für CVE-2024-6387 — Spiegel des Originals 7etsuo/cve-2024-6387-poc |
| 330 | 2026-08-12T11:23:08Z | CVE-2024-0044 | https://github.com/0xbinder/CVE-2024-0044 | CVE-2024-0044: eine „run-as any app“-Schwachstelle mit hohem Schweregrad, die Android-Versionen 12 und 13 betrifft |
| 322 | 2026-09-03T14:04:19Z | CVE-2024-4577 | https://github.com/watchtowrlabs/CVE-2024-4577 | PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC |
| 135 | 2026-08-18T13:26:58Z | apache-vulnerability-testing | https://github.com/mrmtwoj/apache-vulnerability-testing | Apache HTTP Server Schwachstellen-Testtool |
| 289 | 2026-08-15T23:13:15Z | CVE-2024-30088 | https://github.com/tykawaii98/CVE-2024-30088 | |
| 280 | 2026-09-03T06:39:26Z | CVE-2024-21413 | https://github.com/CMNatic/CVE-2024-21413 | CVE-2024-21413 PoC für THM Lab |
| 3553 | 2026-09-03T02:30:53Z | xzbot | https://github.com/amlweems/xzbot | Notizen, Honeypot und Exploit-Demo für die xz-Backdoor (CVE-2024-3094) |
| 207 | 2026-08-06T10:48:24Z | CVE-2024-23897 | https://github.com/h4x0r-dz/CVE-2024-23897 | CVE-2024-23897 |
| 770 | 2026-09-03T01:08:20Z | CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability | https://github.com/xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability | Microsoft-Outlook-Remote-Code-Execution-Vulnerability |
| 203 | 2026-08-31T10:28:00Z | CVE-2024-4367-PoC | https://github.com/LOURC0D3/CVE-2024-4367-PoC | CVE-2024-4367 & CVE-2024-34342 Proof of Concept |
| 271 | 2026-08-28T14:55:35Z | CVE-2024-49138-POC | https://github.com/MrAle98/CVE-2024-49138-POC | POC-Exploit für CVE-2024-49138 |
| 194 | 2026-08-29T10:01:47Z | CVE-2024-6387 | https://github.com/Karmakstylez/CVE-2024-6387 | Remote Unauthenticated Code Execution Vulnerability im OpenSSH-Server (CVE-2024-6387) |
| 9 | 2026-08-15T23:13:20Z | CVE-2024-38077-POC | https://github.com/SecStarBot/CVE-2024-38077-POC | |
| 235 | 2026-07-27T12:00:41Z | CVE_2024_30078_POC_WIFI | https://github.com/blkph0x/CVE_2024_30078_POC_WIFI | Grundkonzept für den neuesten Windows-WLAN-Treiber-CVE |
| 180 | 2026-08-10T14:45:08Z | CVE-2024-25600 | https://github.com/Chocapikk/CVE-2024-25600 | Unauthentifizierte Remote-Code-Ausführung – Bricks <= 1.9.6 |
| 217 | 2026-08-22T03:10:54Z | CVE-2024-21111 | https://github.com/mansk1es/CVE-2024-21111 | Oracle VirtualBox Rechteerweiterung (Lokale Rechteerweiterung) Schwachstelle |
| 136 | 2026-08-15T23:13:25Z | CVE-2024-7479_CVE-2024-7481 | https://github.com/PeterGabaldon/CVE-2024-7479_CVE-2024-7481 | TeamViewer Benutzer-zu-Kernel-Rechteerweiterung PoC. CVE-2024-7479 und CVE-2024-7481. ZDI-24-1289 und ZDI-24-1290. TV-2024-1006. |
| 147 | 2026-08-10T13:29:55Z | CVE-2024-38200 | https://github.com/passtheticket/CVE-2024-38200 | CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Offenlegungsschwachstelle |
| 81 | 2026-07-27T12:00:40Z | CVE-2024-30078- | https://github.com/lvyitian/CVE-2024-30078- | CVE-2024-30078 Erkennungs- und Befehlsausführungsskript |
| 87 | 2026-08-15T22:24:27Z | CVE-2024-40725-CVE-2024-40898 | https://github.com/TAM-K592/CVE-2024-40725-CVE-2024-40898 | CVE-2024-40725 und CVE-2024-40898, die Apache HTTP Server Versionen 2.4.0 bis 2.4.61 betreffen. Diese Schwachstellen stellen erhebliche Risiken für Webserver weltweit dar und können potenziell zu Quellcode-Offenlegung und Server-Side Request Forgery (SSRF)-Angriffen führen. |
| 112 | 2026-08-30T11:11:36Z | CVE-2024-6387 | https://github.com/l0n3m4n/CVE-2024-6387 | PoC - Remote Unauthenticated Code Execution Vulnerability im OpenSSH-Server (Scanner und Exploit) |
| 158 | 2026-08-24T03:27:37Z | CVE-2024-21413 | https://github.com/duy-31/CVE-2024-21413 | Microsoft Outlook Information Disclosure Vulnerability (Passwort-Hash-Leak) - Expect Script POC |
| star | updated_at | name | url | des |
| --- | --- | --- | --- | --- |
| 419 | 2026-07-27T12:00:10Z | qq-tim-elevation | https://github.com/vi3t1/qq-tim-elevation | CVE-2023-34312 |
| 1489 | 2026-09-01T15:26:22Z | cvelist | https://github.com/CVEProject/cvelist | Pilotprogramm für die CVE-Einreichung über GitHub. CVE Record Submission via Pilot PRs ending 6/30/2023 |
| 506 | 2026-08-21T11:19:59Z | Windows_LPE_AFD_CVE-2023-21768 | https://github.com/chompie1337/Windows_LPE_AFD_CVE-2023-21768 | LPE-Exploit für CVE-2023-21768 |
| 782 | 2026-07-29T17:11:08Z | CVE-2023-38831-winrar-exploit | https://github.com/b1tg/CVE-2023-38831-winrar-exploit | CVE-2023-38831 WinRAR-Exploit-Generator |
| 383 | 2026-09-05T06:31:33Z | CVE-2023-32233 | https://github.com/Liuk3r/CVE-2023-32233 | CVE-2023-32233: Sicherheitslücke im Linux-Kernel |
| 394 | 2026-09-05T21:48:15Z | CVE-2023-4911 | https://github.com/leesh3288/CVE-2023-4911 | PoC für CVE-2023-4911 |
| 418 | 2026-07-27T12:00:05Z | CVE-2023-0386 | https://github.com/xkaneiki/CVE-2023-0386 | CVE-2023-0386 Privilegieneskalation auf Ubuntu 22.04 |
| 116 | 2026-08-24T14:52:11Z | CVE-2023-21839 | https://github.com/ASkyeye/CVE-2023-21839 | Weblogic CVE-2023-21839 RCE (Ein-Klick-RCE ohne Java-Abhängigkeiten) |
| 328 | 2026-08-18T21:26:43Z | CVE-2023-21752 | https://github.com/Wh04m1001/CVE-2023-21752 | |
| 652 | 2026-09-05T14:40:10Z | keepass-password-dumper | https://github.com/vdohney/keepass-password-dumper | Original-PoC für CVE-2023-32784 |
| 283 | 2026-07-30T00:43:58Z | CVE-2023-21608 | https://github.com/hacksysteam/CVE-2023-21608 | Adobe Acrobat Reader - CVE-2023-21608 - Remote-Code-Execution-Exploit |
| 317 | 2026-08-20T20:28:38Z | CVE-2023-4863 | https://github.com/mistymntncop/CVE-2023-4863 | |
| 242 | 2026-08-21T11:20:13Z | CVE-2023-36874 | https://github.com/Wh04m1001/CVE-2023-36874 | |
| 247 | 2026-08-14T12:24:08Z | CVE-2023-44487 | https://github.com/bcdannyboy/CVE-2023-44487 | Einfaches Schwachstellen-Scanning, um festzustellen, ob Webserver für CVE-2023-44487 anfällig sein könnten |
| 228 | 2026-07-29T15:55:14Z | CVE-2023-3519 | https://github.com/BishopFox/CVE-2023-3519 | RCE-Exploit für CVE-2023-3519 |
| 245 | 2026-08-10T14:45:02Z | CVE-2023-7028 | https://github.com/Vozec/CVE-2023-7028 | Dieses Repository präsentiert einen Proof-of-Concept für CVE-2023-7028 |
| 169 | 2026-07-12T21:14:55Z | CVE-2023-36745 | https://github.com/N1k0la-T/CVE-2023-36745 | |
| 140 | 2026-08-09T23:29:11Z | CVE-2023-34362 | https://github.com/horizon3ai/CVE-2023-34362 | MOVEit CVE-2023-34362 |
| 228 | 2026-08-25T15:16:27Z | CVE-2023-20887 | https://github.com/sinsinology/CVE-2023-20887 | VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887) |
| 345 | 2026-09-03T19:51:33Z | CVE-2023-23397-POC-Powershell | https://github.com/api0cradle/CVE-2023-23397-POC-Powershell | |
| 183 | 2026-08-15T23:12:53Z | CVE-2023-28252 | https://github.com/fortra/CVE-2023-28252 | |
| 136 | 2026-08-15T22:24:27Z | CVE-2023-2640-CVE-2023-32629 | https://github.com/g1vi/CVE-2023-2640-CVE-2023-32629 | GameOver(lay) Ubuntu-Privilegieneskalation |
| 289 | 2026-08-08T13:06:40Z | CVE-2023-25690-POC | https://github.com/dhmosfunk/CVE-2023-25690-POC | CVE 2023 25690 Proof of Concept - anfällige mod_proxy-Konfiguration auf Apache HTTP Server Versionen 2.4.0 - 2.4.55 führt zu einer HTTP-Request-Smuggling-Schwachstelle. |
| 241 | 2026-08-06T11:26:50Z | Weblogic-CVE-2023-21839 | https://github.com/DXask88MA/Weblogic-CVE-2023-21839 | |
| 206 | 2026-08-31T13:38:48Z | CVE-2023-46747-RCE | https://github.com/W01fh4cker/CVE-2023-46747-RCE | Exploit für f5-big-ip RCE cve-2023-46747 |
| 153 | 2026-09-04T10:06:50Z | cve-2023-29360 | https://github.com/Nero22k/cve-2023-29360 | Exploit für CVE-2023-29360, der auf den MSKSSRV.SYS-Treiber abzielt |
| 237 | 2026-09-03T19:51:42Z | CVE-2023-29357 | https://github.com/Chocapikk/CVE-2023-29357 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| 167 | 2026-08-17T13:31:52Z | CVE-2023-25157 | https://github.com/win3zz/CVE-2023-25157 | CVE-2023-25157 - GeoServer SQL Injection - PoC |
| 165 | 2026-07-23T03:14:23Z | Windows_MSKSSRV_LPE_CVE-2023-36802 | https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802 | LPE-Exploit für CVE-2023-36802 |
| 158 | 2026-08-21T11:20:01Z | CVE-2023-23397_EXPLOIT_0DAY | https://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY | Exploit für CVE-2023-23397 |
| star | updated_at | name | url | des |
|---|
| 438 | 2026-09-05T06:31:04Z | CVE-2022-25636 | https://github.com/Bonfee/CVE-2022-25636 | CVE-2022-25636 |
| 461 | 2026-08-28T14:55:07Z | CVE-2022-21882 | https://github.com/KaLendsi/CVE-2022-21882 | win32k LPE |
| 1133 | 2026-08-26T03:57:20Z | CVE-2022-0847-DirtyPipe-Exploit | https://github.com/Arinerron/CVE-2022-0847-DirtyPipe-Exploit | Ein Root-Exploit für CVE-2022-0847 (Dirty Pipe) |
| 379 | 2026-07-11T17:00:38Z | CVE-2022-0185 | https://github.com/Crusaders-of-Rust/CVE-2022-0185 | CVE-2022-0185 |
| 673 | 2026-07-23T03:14:03Z | CVE-2022-29072 | https://github.com/kagancapar/CVE-2022-29072 | 7-Zip bis 21.07 unter Windows ermöglicht Privilegieneskalation und Befehlsausführung, wenn eine Datei mit der Erweiterung .7z in den Bereich Hilfe>Inhalt gezogen wird. |
| 497 | 2026-09-01T03:56:02Z | CVE-2022-0995 | https://github.com/Bonfee/CVE-2022-0995 | CVE-2022-0995 Exploit |
| 573 | 2026-08-24T11:54:59Z | CVE-2022-23222 | https://github.com/tr3ee/CVE-2022-23222 | CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation |
| 528 | 2026-07-11T17:03:47Z | OpenSSL-2022 | https://github.com/NCSC-NL/OpenSSL-2022 | Betriebliche Informationen zu CVE-2022-3602 und CVE-2022-3786, zwei Schwachstellen in OpenSSL 3 |
| 223 | 2026-05-13T19:49:24Z | Spring-Cloud-Gateway-CVE-2022-22947 | https://github.com/lucksec/Spring-Cloud-Gateway-CVE-2022-22947 | CVE-2022-22947 |
| 360 | 2026-08-18T21:14:11Z | CVE-2022-21907 | https://github.com/ZZ-SOCMAP/CVE-2022-21907 | HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907 |
| 377 | 2026-08-21T11:19:25Z | CVE-2022-29464 | https://github.com/hakivvi/CVE-2022-29464 | WSO2 RCE (CVE-2022-29464) Exploit und Writeup. |
| 732 | 2026-09-05T06:19:39Z | CVE-2022-0847-DirtyPipe-Exploits | https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits | Eine Sammlung von Exploits und Dokumentation, die zur Ausnutzung der Linux Dirty Pipe-Schwachstelle verwendet werden können. |
| 358 | 2026-09-01T19:54:28Z | CVE-2022-40684 | https://github.com/horizon3ai/CVE-2022-40684 | Ein Proof-of-Concept-Exploit für CVE-2022-40684, der Fortinet FortiOS, FortiProxy und FortiSwitchManager betrifft |
| 487 | 2026-08-21T11:19:45Z | CVE-2022-2588 | https://github.com/Markakd/CVE-2022-2588 | Exploit für CVE-2022-2588 |
| 387 | 2026-07-27T14:08:58Z | CVE-2022-39197 | https://github.com/its-arun/CVE-2022-39197 | CobaltStrike <= 4.7.1 RCE |
| 414 | 2026-09-03T19:51:26Z | CVE-2022-33679 | https://github.com/Bdenneu/CVE-2022-33679 | One day basierend auf https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html |
| 282 | 2026-06-22T01:47:59Z | CVE-2022-0847 | https://github.com/r1is/CVE-2022-0847 | CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 ist eine lokale Privilegieneskalations-Schwachstelle, die in Linux-Kernel 5.8 und späteren Versionen existiert. Durch Ausnutzung dieser Schwachstelle kann ein Angreifer Daten in beliebigen lesbaren Dateien überschreiben und so einen Benutzer mit normalen Berechtigungen zu privilegiertem root erheben. Das Prinzip der CVE-2022-0847-Schwachstelle ähnelt der CVE-2016-5195 Dirty Cow-Schwachstelle, ist jedoch einfacher auszunutzen. Der Autor der Schwachstelle nannte sie "Dirty Pipe" |
| 353 | 2026-08-20T09:45:56Z | CVE-2022-21894 | https://github.com/Wack0/CVE-2022-21894 | baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability |
| 325 | 2026-07-31T14:19:06Z | Spring4Shell-POC | https://github.com/reznok/Spring4Shell-POC | Dockerisierte Spring4Shell (CVE-2022-22965) PoC-Anwendung und Exploit |
| 460 | 2026-08-24T08:16:08Z | CVE-2022-27254 | https://github.com/nonamecoder/CVE-2022-27254 | PoC für eine Schwachstelle in Hondas Remote Keyless System (CVE-2022-27254) |
| 317 | 2026-06-22T11:04:03Z | CVE-2022-39197-patch | https://github.com/burpheart/CVE-2022-39197-patch | CVE-2022-39197 漏洞补丁. CVE-2022-39197 Vulnerability Patch. |
| 597 | 2026-09-05T18:21:18Z | CVE-2022-38694_unlock_bootloader | https://github.com/TomKing062/CVE-2022-38694_unlock_bootloader | Dies ist eine einmalige Umgehung der Signaturüberprüfung. Für eine dauerhafte Umgehung der Signaturüberprüfung siehe https://github.com/TomKing062/CVE-2022-38691_38692 |
| 302 | 2026-07-26T11:42:14Z | CVE-2022-21971 | https://github.com/0vercl0k/CVE-2022-21971 | PoC für CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability" |
| 265 | 2026-04-05T11:55:32Z | CVE-2022-39952 | https://github.com/horizon3ai/CVE-2022-39952 | POC für CVE-2022-39952 |
| 284 | 2026-08-24T14:52:04Z | cve-2022-27255 | https://github.com/infobyte/cve-2022-27255 | |
| 238 | 2026-08-24T14:51:59Z | CVE-2022-20699 | https://github.com/Audiobahn/CVE-2022-20699 | Cisco Anyconnect VPN unauth RCE (rwx stack) |
| 236 | 2026-08-31T15:38:57Z | CVE-2022-30075 | https://github.com/aaronsvk/CVE-2022-30075 | Tp-Link Archer AX50 Authenticated RCE (CVE-2022-30075) |
| 219 | 2026-06-02T12:40:09Z | CVE-2022-34918 | https://github.com/veritas501/CVE-2022-34918 | CVE-2022-34918 netfilter nf_tables lokale Privilegieneskalation POC |
| 115 | 2026-07-03T14:59:15Z | CVE-2022-22963 | https://github.com/dinosn/CVE-2022-22963 | CVE-2022-22963 PoC |
| 197 | 2026-07-13T09:28:39Z | CVE-2022-21882 | https://github.com/L4ys/CVE-2022-21882 |
| star | updated_at | name | url | des |
|---|
| 1414 | 2026-09-01T15:26:24Z | noPac | https://github.com/cube0x0/noPac | CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter. |
| 2001 | 2026-09-06T00:10:43Z | CVE-2021-1675 | https://github.com/cube0x0/CVE-2021-1675 | C#- und Impacket-Implementierung von PrintNightmare CVE-2021-1675/CVE-2021-34527 |
| 2048 | 2026-09-01T15:26:33Z | CVE-2021-4034 | https://github.com/berdav/CVE-2021-4034 | CVE-2021-4034 1day |
| 1808 | 2026-09-05T22:53:02Z | CVE-2021-40444 | https://github.com/lockedbyte/CVE-2021-40444 | CVE-2021-40444 PoC |
| 1162 | 2026-09-05T06:04:24Z | CVE-2021-4034 | https://github.com/arthepsy/CVE-2021-4034 | PoC für PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034) |
| 1023 | 2026-09-05T05:48:21Z | CVE-2021-3156 | https://github.com/blasty/CVE-2021-3156 | |
| 1108 | 2026-09-04T02:10:14Z | CVE-2021-1675 | https://github.com/calebstewart/CVE-2021-1675 | Reine PowerShell-Implementierung von CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare) |
| 497 | 2026-09-03T19:51:00Z | CVE-2021-21972 | https://github.com/NS-Sp4ce/CVE-2021-21972 | CVE-2021-21972 Exploit |
| 1067 | 2026-08-23T03:16:37Z | sam-the-admin | https://github.com/safebuffer/sam-the-admin | Ausnutzung von CVE-2021-42278 und CVE-2021-42287 zur Identitätsübernahme als DA von einem Standard-Domänenbenutzer aus |
| 804 | 2026-08-26T08:10:59Z | CVE-2021-3156 | https://github.com/worawit/CVE-2021-3156 | Sudo Baron Samedit Exploit |
| 833 | 2026-09-03T02:54:08Z | CVE-2021-40444 | https://github.com/klezVirus/CVE-2021-40444 | CVE-2021-40444 - Vollständig weaponisierter Microsoft Office Word RCE-Exploit |
| 426 | 2026-08-23T20:16:03Z | CVE-2021-1732-Exploit | https://github.com/KaLendsi/CVE-2021-1732-Exploit | CVE-2021-1732 Exploit |
| 1023 | 2026-09-05T23:38:24Z | noPac | https://github.com/Ridter/noPac | Ausnutzung von CVE-2021-42278 und CVE-2021-42287 zur Identitätsübernahme als DA von einem Standard-Domänenbenutzer aus |
| 827 | 2026-07-31T15:53:30Z | CVE-2021-31166 | https://github.com/0vercl0k/CVE-2021-31166 | Proof of Concept für CVE-2021-31166, ein remote ausgelöster HTTP.sys Use-after-free. |
| 860 | 2026-08-17T13:31:50Z | CVE-2021-44228-Scanner | https://github.com/logpresso/CVE-2021-44228-Scanner | Schwachstellen-Scanner und Mitigations-Patch für Log4j2 CVE-2021-44228 |
| 1848 | 2026-09-04T08:37:46Z | log4j-shell-poc | https://github.com/kozmer/log4j-shell-poc | Ein Proof-Of-Concept für die CVE-2021-44228-Schwachstelle. |
| 1141 | 2026-08-30T16:31:59Z | log4shell-vulnerable-app | https://github.com/christophetd/log4shell-vulnerable-app | Spring Boot-Webanwendung, anfällig für Log4Shell (CVE-2021-44228). |
| 443 | 2026-09-03T09:48:19Z | CVE-2021-3493 | https://github.com/briskets/CVE-2021-3493 | Ubuntu OverlayFS Local Privesc |
| 325 | 2026-05-31T05:04:48Z | CVE-2021-1675-LPE | https://github.com/hlldz/CVE-2021-1675-LPE | Local Privilege Escalation Edition für CVE-2021-1675/CVE-2021-34527 |
| 186 | 2026-07-17T09:01:22Z | exprolog | https://github.com/herwonowr/exprolog | ProxyLogon Full Exploit Chain PoC (CVE-2021–26855, CVE-2021–26857, CVE-2021–26858, CVE-2021–27065) |
| 439 | 2026-06-20T15:36:09Z | log4j-finder | https://github.com/fox-it/log4j-finder | Findet anfällige Log4j2-Versionen auf der Festplatte sowie in Java-Archivdateien (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105) |
| 429 | 2026-07-29T10:34:22Z | CVE-2021-3156 | https://github.com/stong/CVE-2021-3156 | PoC für CVE-2021-3156 (sudo Heap Overflow) |
| 176 | 2026-08-17T13:31:49Z | ProxyVulns | https://github.com/hosch3n/ProxyVulns | [ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell] CVE-2021-34473 & CVE-2021-34523 & CVE-2021-31207 Exploit Chains. |
| 287 | 2026-08-28T07:19:34Z | CVE-2021-22205 | https://github.com/Al1ex/CVE-2021-22205 | CVE-2021-22205& GitLab CE/EE RCE |
| 3422 | 2026-08-24T02:07:57Z | log4j-scan | https://github.com/fullhunt/log4j-scan | Ein vollautomatischer, präziser und umfangreicher Scanner zum Auffinden von log4j RCE CVE-2021-44228 |
| 268 | 2026-09-03T19:51:00Z | CVE-2021-21972 | https://github.com/horizon3ai/CVE-2021-21972 | Proof of Concept Exploit für vCenter CVE-2021-21972 |
| 301 | 2026-09-04T02:23:31Z | CVE-2021-36260 | https://github.com/Aiminsun/CVE-2021-36260 | Command-Injection-Schwachstelle im Webserver einiger Hikvision-Produkte. Aufgrund unzureichender Eingabevalidierung kann ein Angreifer die Schwachstelle ausnutzen, um einen Command-Injection-Angriff durch das Senden von Nachrichten mit bösartigen Befehlen zu starten. |
| 147 | 2026-05-23T10:52:31Z | CVE-2021-41773_CVE-2021-42013 | https://github.com/inbug-team/CVE-2021-41773_CVE-2021-42013 | CVE-2021-41773 CVE-2021-42013 Schwachstellen-Massenprüfungstool |
| 325 | 2026-08-21T18:45:26Z | CVE-2021-34527 | https://github.com/JohnHammond/CVE-2021-34527 | |
| 122 | 2026-09-03T09:07:12Z | proxyshell | https://github.com/horizon3ai/proxyshell | Proof of Concept für CVE-2021-34473, CVE-2021-34523 und CVE-2021-31207 |
| star | updated_at | name | url | des |
|---|
| 4289 | 2026-09-04T01:55:44Z | exphub | https://github.com/zhzyker/exphub | Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340 |
| 1832 | 2026-09-01T15:26:49Z | CVE-2020-1472 | https://github.com/bvcyber/CVE-2020-1472 | Testtool für CVE-2020-1472 |
| 2075 | 2026-09-01T15:26:20Z | weblogicScanner | https://github.com/0xn0ne/weblogicScanner | weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883 |
| 1359 | 2026-08-21T11:17:52Z | CVE-2020-0796 | https://github.com/danigargu/CVE-2020-0796 | CVE-2020-0796 - Windows SMBv3 LPE Exploit #SMBGhost |
| 1323 | 2026-09-03T13:04:39Z | CVE-2020-1472 | https://github.com/dirkjanm/CVE-2020-1472 | PoC für Zerologon - alle Forschungsanerkennung geht an Tom Tervoort von Secura |
| 287 | 2026-08-04T08:01:02Z | CVE-2020-14882 | https://github.com/jas502n/CVE-2020-14882 | CVE-2020–14882、CVE-2020–14883 |
| 328 | 2026-08-05T23:19:15Z | cve-2020-0688 | https://github.com/Ridter/cve-2020-0688 | cve-2020-0688 |
| 706 | 2026-09-02T23:02:20Z | zerologon | https://github.com/risksense/zerologon | Exploit für zerologon cve-2020-1472 |
| 722 | 2026-09-04T16:53:43Z | SMBGhost | https://github.com/ly4k/SMBGhost | Scanner für CVE-2020-0796 - SMBv3 RCE |
| 353 | 2026-09-04T00:17:18Z | CVEAC-2020 | https://github.com/thesecretclub/CVEAC-2020 | EasyAntiCheat Integritätsprüfungs-Umgehung durch Nachahmung von Speicheränderungen |
| 571 | 2026-08-15T23:12:11Z | CVE-2020-0796-RCE-POC | https://github.com/jamf/CVE-2020-0796-RCE-POC | CVE-2020-0796 Remote Code Execution POC |
| 374 | 2025-12-23T08:30:40Z | CVE-2020-5902 | https://github.com/jas502n/CVE-2020-5902 | CVE-2020-5902 BIG-IP |
| 133 | 2026-07-03T05:20:29Z | CVE_2020_2546 | https://github.com/hktalent/CVE_2020_2546 | CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 Payload Exploit PoC Python3, |
| 223 | 2026-07-29T10:34:10Z | SAP_RECON | https://github.com/chipik/SAP_RECON | PoC für CVE-2020-6287, CVE-2020-6286 (SAP RECON-Schwachstelle) |
| 889 | 2026-08-11T23:19:25Z | CurveBall | https://github.com/ly4k/CurveBall | PoC für CVE-2020-0601 - Windows CryptoAPI (Crypt32.dll) |
| 294 | 2026-08-04T08:00:45Z | CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner | https://github.com/bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner | Cnvd-2020-10487 / cve-2020-1938, Scanner-Tool |
| 336 | 2026-08-04T08:00:45Z | CVE-2020-2551 | https://github.com/Y4er/CVE-2020-2551 | Weblogic IIOP CVE-2020-2551 |
| 249 | 2026-05-28T08:01:05Z | BlueGate | https://github.com/ly4k/BlueGate | PoC (DoS + Scanner) für CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE |
| 354 | 2026-08-05T23:16:25Z | CVE-2020-0688 | https://github.com/zcgonvh/CVE-2020-0688 | Exploit- und Erkennungstools für CVE-2020-0688 |
| 721 | 2026-08-13T09:49:27Z | CVE-2020-0787-EXP-ALL-WINDOWS-VERSION | https://github.com/cbwang505/CVE-2020-0787-EXP-ALL-WINDOWS-VERSION | Unterstützt ALLE Windows-Versionen |
| 101 | 2026-04-03T14:54:58Z | dnspooq | https://github.com/knqyf263/dnspooq | DNSpooq - dnsmasq Cache Poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685) |
| 331 | 2026-09-03T11:41:49Z | CVE-2020-0796-PoC | https://github.com/eerykitty/CVE-2020-0796-PoC | PoC zum Auslösen eines Buffer Overflows über CVE-2020-0796 |
| 398 | 2026-08-21T13:18:39Z | CVE-2020-1472 | https://github.com/VoidSec/CVE-2020-1472 | Exploit-Code für CVE-2020-1472 alias Zerologon |
| 163 | 2026-08-04T08:00:45Z | cve-2020-0688 | https://github.com/random-robbie/cve-2020-0688 | cve-2020-0688 |
| 257 | 2026-07-29T10:33:57Z | CVE-2020-0041 | https://github.com/bluefrostsecurity/CVE-2020-0041 | Exploits für Android Binder Bug CVE-2020-0041 |
| 423 | 2026-08-19T17:33:57Z | Ghostcat-CNVD-2020-10487 | https://github.com/00theway/Ghostcat-CNVD-2020-10487 | Ghostcat Datei lesen/Code ausführen, CNVD-2020-10487 (CVE-2020-1938) |
| 514 | 2026-09-05T02:17:56Z | CVE-2020-15368 | https://github.com/stong/CVE-2020-15368 | CVE-2020-15368, alias "How to exploit a vulnerable driver" |
| 335 | 2026-06-30T12:15:45Z | chainoffools | https://github.com/kudelskisecurity/chainoffools | Ein PoC für CVE-2020-0601 |
| 337 | 2026-09-03T19:45:36Z | CVE-2020-0683 | https://github.com/padovah4ck/CVE## 2019 | |
| star | updated_at | name | url | des |
| --- | --- | --- | --- | --- |
| 2075 | 2026-09-01T15:26:20Z | weblogicScanner | https://github.com/0xn0ne/weblogicScanner | weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883 |
| 4289 | 2026-09-04T01:55:44Z | exphub | https://github.com/zhzyker/exphub | Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340 |
| 1832 | 2026-09-04T16:09:45Z | phuip-fpizdam | https://github.com/neex/phuip-fpizdam | Exploit für CVE-2019-11043 |
| 1182 | 2026-09-04T00:56:48Z | BlueKeep | https://github.com/Ekultek/BlueKeep | Proof of Concept für CVE-2019-0708 |
| 496 | 2026-09-01T03:59:50Z | CVE-2019-0708 | https://github.com/n1xbyte/CVE-2019-0708 | dump |
| 658 | 2026-07-29T10:32:54Z | CVE-2019-5736-PoC | https://github.com/Frichetten/CVE-2019-5736-PoC | PoC für CVE-2019-5736 |
| 388 | 2026-08-04T08:00:31Z | CVE-2019-0708 | https://github.com/k8gege/CVE-2019-0708 | 3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check) |
| 821 | 2026-08-18T00:34:19Z | esp32_esp8266_attacks | https://github.com/Matheus-Garbelini/esp32_esp8266_attacks | Proof of Concept der ESP32/8266 Wi-Fi-Schwachstellen (CVE-2019-12586, CVE-2019-12587, CVE-2019-12588) |
| 433 | 2026-05-23T10:50:00Z | CVE-2019-2725 | https://github.com/lufeirider/CVE-2019-2725 | CVE-2019-2725 命令回显 |
| 573 | 2026-07-16T11:27:46Z | cve-2019-19781 | https://github.com/trustedsec/cve-2019-19781 | Dies ist ein veröffentlichtes Tool für die Citrix ADC (NetScaler)-Schwachstelle. Wir veröffentlichen es nur, weil andere den Exploit-Code zuerst veröffentlicht haben. |
| 348 | 2026-07-29T10:33:39Z | COMahawk | https://github.com/apt69/COMahawk | Privilege Escalation: Waffenisierung von CVE-2019-1405 und CVE-2019-1322 |
| 360 | 2026-07-29T10:33:28Z | CVE-2019-11510 | https://github.com/projectzeroindia/CVE-2019-11510 | Exploit für beliebiges Dateilesen auf Pulse Secure SSL VPN (CVE-2019-11510) |
| 367 | 2026-07-16T11:27:44Z | CVE-2019-19781 | https://github.com/projectzeroindia/CVE-2019-19781 | Remote-Code-Execution-Exploit für Citrix Application Delivery Controller und Citrix Gateway [ CVE-2019-19781 ] |
| 333 | 2026-09-01T07:22:52Z | CVE-2019-13272 | https://github.com/jas502n/CVE-2019-13272 | Linux 4.10 < 5.1.17 PTRACE_TRACEME lokaler Root |
| 624 | 2026-07-29T10:33:33Z | CVE-2019-11708 | https://github.com/0vercl0k/CVE-2019-11708 | Vollständige Exploit-Kette (CVE-2019-11708 & CVE-2019-9810) gegen Firefox auf Windows 64-Bit. |
| 129 | 2026-07-29T10:33:01Z | CVE-2019-0604 | https://github.com/linhlhq/CVE-2019-0604 | CVE-2019-0604 |
| 374 | 2026-08-18T07:57:54Z | CVE-2019-18935 | https://github.com/noperator/CVE-2019-18935 | RCE-Exploit für eine .NET JSON-Deserialisierungsschwachstelle in Telerik UI für ASP.NET AJAX. |
| 316 | 2026-07-29T10:32:54Z | cve-2019-1003000-jenkins-rce-poc | https://github.com/adamyordan/cve-2019-1003000-jenkins-rce-poc | Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative) |
| 239 | 2026-07-29T10:33:05Z | CVE-2019-0841 | https://github.com/rogue-kdc/CVE-2019-0841 | PoC-Code für die Privilege-Escalation-Schwachstelle CVE-2019-0841 |
| 209 | 2026-08-25T09:51:16Z | CVE-2019-11932 | https://github.com/awakened1712/CVE-2019-11932 | Einfacher POC zur Ausnutzung des WhatsApp-Double-Free-Bugs in DDGifSlurp in decoding.c in libpl_droidsonroids_gif |
| 255 | 2026-08-29T12:30:21Z | CVE-2019-5786 | https://github.com/exodusintel/CVE-2019-5786 | FileReader Exploit |
| 267 | 2026-05-13T19:46:49Z | CVE-2019-11932 | https://github.com/dorkerdevil/CVE-2019-11932 | double-free bug in WhatsApp exploit poc |
| 921 | 2026-09-01T01:54:30Z | rdpscan | https://github.com/robertdavidgraham/rdpscan | Ein schneller Scanner für die CVE-2019-0708 "BlueKeep"-Schwachstelle. |
| 293 | 2026-08-28T14:54:44Z | bluekeep | https://github.com/0xeb-bp/bluekeep | Öffentliche Arbeit für CVE-2019-0708 |
| 249 | 2026-09-02T19:00:40Z | CVE-2019-1040 | https://github.com/Ridter/CVE-2019-1040 | CVE-2019-1040 mit Exchange |
| 681 | 2026-07-29T10:32:53Z | dirty_sock | https://github.com/initstring/dirty_sock | Linux-Privilege-Escalation-Exploit über snapd (CVE-2019-7304) |
| 166 | 2026-07-29T10:33:36Z | CVE-2019-7609 | https://github.com/LandGrey/CVE-2019-7609 | exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts |
| 3 | 2025-09-14T06:41:42Z | CVE-2019-0708 | https://github.com/victor0013/CVE-2019-0708 | Scanner PoC für CVE-2019-0708 RDP RCE vuln |
| 200 | 2026-09-01T04:11:59Z | CVE-2019-16098 | https://github.com/Barakat/CVE-2019-16098 | Lokaler Privilege-Escalation-PoC-Exploit für CVE-2019-16098 |
| 208 | 2026-07-29T10:32:58Z | CVE-2019-0192 | https://github.com/mpgn/CVE-2019-0192 | RCE auf Apache Solr mittels Deserialisierung nicht vertrauenswürdiger Daten über jmx.serviceUrl |
| star | updated_at | name | url | des |
|---|
| 2075 | 2026-09-01T15:26:20Z | weblogicScanner | https://github.com/0xn0ne/weblogicScanner | weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883 |
| 499 | 2026-09-02T21:00:11Z | CVE-2018-8120 | https://github.com/rip1s/CVE-2018-8120 | CVE-2018-8120 Windows LPE exploit |
| 493 | 2026-08-11T09:12:24Z | CVE-2018-20250 | https://github.com/WyAtu/CVE-2018-20250 | exp für https://research.checkpoint.com/extracting-code-execution-from-winrar |
| 534 | 2026-07-03T09:06:47Z | CVE-2018-15473-Exploit | https://github.com/Rhynorater/CVE-2018-15473-Exploit | In Python geschriebener Exploit für CVE-2018-15473 mit Threading und Exportformaten |
| 558 | 2026-09-05T01:15:33Z | CVE-2018-9995_dvr_credentials | https://github.com/ezelf/CVE-2018-9995_dvr_credentials | (CVE-2018-9995) DVR-Anmeldedaten abrufen |
| 369 | 2026-07-29T10:32:50Z | Exchange2domain | https://github.com/Ridter/Exchange2domain | CVE-2018-8581 |
| 253 | 2026-05-18T02:43:52Z | CVE-2018-13379 | https://github.com/milo2012/CVE-2018-13379 | CVE-2018-13379 |
| 497 | 2026-09-01T03:57:01Z | CVE-2018-10933 | https://github.com/blacknbunny/CVE-2018-10933 | Shell ohne jegliche Anmeldedaten mittels CVE-2018-10933 (LibSSH) starten |
| 270 | 2026-07-14T20:29:03Z | CVE-2018-0802 | https://github.com/rxwx/CVE-2018-0802 | PoC-Exploit für CVE-2018-0802 (und optional CVE-2017-11882) |
| 354 | 2026-08-13T09:14:55Z | CVE-2018-7600 | https://github.com/a2u/CVE-2018-7600 | 💀Proof-of-Concept für CVE-2018-7600 Drupal SA-CORE-2018-002 |
| 293 | 2026-09-02T21:43:04Z | CVE-2018-8120 | https://github.com/alpha1ab/CVE-2018-8120 | CVE-2018-8120 Exploit für Win2003 Win2008 WinXP Win7 |
| 423 | 2026-09-02T11:17:08Z | CVE-2018-8897 | https://github.com/can1357/CVE-2018-8897 | Beliebige Codeausführung mit Kernel-Rechten mittels CVE-2018-8897. |
| 331 | 2026-04-11T08:21:35Z | CVE-2018-8581 | https://github.com/WyAtu/CVE-2018-8581 | CVE-2018-8581 |
| 520 | 2026-08-16T20:26:51Z | WinboxPoC | https://github.com/BasuCert/WinboxPoC | Proof of Concept der kritischen Winbox-Schwachstelle (CVE-2018-14847) |
| 78 | 2024-08-12T19:37:50Z | CVE-2018-2628 | https://github.com/shengqi158/CVE-2018-2628 | CVE-2018-2628 & CVE-2018-2893 |
| 146 | 2026-05-13T19:46:39Z | CVE-2018-13382 | https://github.com/milo2012/CVE-2018-13382 | CVE-2018-13382 |
| 139 | 2026-07-29T10:32:13Z | CVE-2018-8174_EXP | https://github.com/Yt1g3r/CVE-2018-8174_EXP | CVE-2018-8174_python |
| 205 | 2026-07-29T10:32:16Z | CVE-2018-0296 | https://github.com/yassineaboukir/CVE-2018-0296 | Skript zum Testen der Cisco ASA Path-Traversal-Schwachstelle (CVE-2018-0296) und zum Extrahieren von Systeminformationen. |
| 172 | 2025-12-24T02:23:23Z | CVE-2018-3245 | https://github.com/pyn3rd/CVE-2018-3245 | CVE-2018-3245-PoC |
| 303 | 2026-06-06T17:24:23Z | struts-pwn_CVE-2018-11776 | https://github.com/mazen160/struts-pwn_CVE-2018-11776 | Ein Exploit für Apache Struts CVE-2018-11776 |
| 163 | 2026-07-29T10:32:10Z | cve-2018-8120 | https://github.com/bigric3/cve-2018-8120 | |
| 140 | 2026-09-03T04:51:18Z | CVE-2018-7600 | https://github.com/pimps/CVE-2018-7600 | Exploit für Drupal 7 <= 7.57 CVE-2018-7600 |
| 375 | 2026-09-06T01:36:10Z | GDRVLoader | https://github.com/zer0condition/GDRVLoader | Nicht signierter Treiber-Loader unter Verwendung von CVE-2018-19320 |
| 179 | 2026-07-13T11:58:32Z | CVE-2018-15982_EXP | https://github.com/Ridter/CVE-2018-15982_EXP | exp von CVE-2018-15982 |
| 119 | 2026-08-01T13:49:38Z | cve-2018-8453-exp | https://github.com/ze0r/cve-2018-8453-exp | cve-2018-8453 exp |
| 166 | 2026-07-29T10:31:41Z | RTF_11882_0802 | https://github.com/Ridter/RTF_11882_0802 | PoC für CVE-2018-0802 und CVE-2017-11882 |
| 167 | 2026-07-29T10:32:12Z | CVE-2018-8174-msf | https://github.com/0x09AL/CVE-2018-8174-msf | CVE-2018-8174 - VBScript-Speicherkorruptions-Exploit. |
| 267 | 2026-07-29T10:32:00Z | credssp | https://github.com/preempt/credssp | Ein Code, der CVE-2018-0886 demonstriert |
| 140 | 2025-11-28T04:31:10Z | CVE-2018-2894 | https://github.com/LandGrey/CVE-2018-2894 | CVE-2018-2894 WebLogic Unrestricted File Upload Lead To RCE Check Script |
| 603 | 2026-09-04T17:58:20Z | Drupalgeddon2 | https://github.com/dreadlocked/Drupalgeddon2 | Exploit für Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002) |